Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DD92961078506C32A1D303E7BBA11C2AF377D314CAB916DA99D197648EE7F70E90F1A6 |
|
CONTENT
ssdeep
|
384:vh31ZphmY6Oc0KzKzXqJklkhu/qT9l9+NEC6:7H6Oc0XeC6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
929a6ccecf31b930 |
|
VISUAL
aHash
|
ffffcfffffff0000 |
|
VISUAL
dHash
|
69e898d878230426 |
|
VISUAL
wHash
|
ff7e4e7e7e000000 |
|
VISUAL
colorHash
|
07006000000 |
|
VISUAL
cropResistant
|
21e09898d8f82200,0000282002020000,0004061616060200 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
Found 2 other scans for this domain